Cyber insurance used to be a short application and a modest premium. Today, many insurers ask detailed questions about your security controls before they will offer coverage, and some decline applicants who lack basic protections. For care facilities, which hold sensitive data and depend on constant system availability, understanding these questions helps you qualify, and the controls they ask about are good practice regardless of insurance.
Insurers have paid out on many ransomware and business email compromise claims. They have learned which controls correlate with fewer and smaller losses, and they now use applications to screen risk. A good set of answers can improve eligibility and may influence the price, though no one can promise a particular outcome.
Expect questions about MFA on email, remote access, administrator accounts and sometimes backups and cloud consoles. This is one of the most common requirements.
Insurers ask how often you back up, whether backups are offline or immutable, whether they are encrypted and whether you test restores. See our article on the 3-2-1 rule for the principles.
Many applications ask whether you run modern endpoint protection beyond traditional antivirus, and whether it is monitored.
Questions often cover how quickly critical security updates are applied and whether you run unsupported systems, such as operating systems that no longer receive updates.
Expect questions about filtering for phishing and malicious attachments, and about email authentication settings.
Insurers ask whether you provide regular security awareness training and phishing simulations.
A written, tested plan is a frequent question, along with whether you have a relationship with a response firm.
How do you control administrator accounts and who can connect from outside your network?
Firewalls, segmentation and monitoring may appear on the form.
Before completing an application, assemble answers with your IT provider. Do not guess. List each question and write down the actual state of the control and the evidence.
This point cannot be overstated. If an application states that MFA is enabled everywhere and it is not, the insurer may deny a claim or rescind the policy after an incident. If a control is partially in place, say so and describe the rollout plan. Have an executive sign only after reviewing the answers.
If you discover missing controls, consider whether you can implement them before submission. MFA and backup improvements are often quick wins.
Save screenshots, policies, training records and test results. If a claim arises, evidence supports your position.
Policies differ widely. Ask your broker about:
First-party costs such as forensic investigation, data restoration, business interruption and extortion
Third-party costs such as legal defense and regulatory proceedings
Breach response services such as notification, call centers and credit monitoring
Coverage for regulatory fines, where insurable by law
Sub-limits, waiting periods and exclusions, such as acts of war or failure to maintain stated security controls
Whether you must use panel vendors for incident response, and how to report a claim quickly
Keep the claims notification number saved outside your computer systems, since email may be down during an incident.
Each renewal brings new questions. Treat it as an annual check-up. Compare answers year to year and note improvements. Share results with leadership so security investments are connected to business outcomes.
Insurance transfers some financial risk but cannot restore trust, reduce disruption to care or guarantee that a claim will be paid. The strongest position combines good controls, tested response plans and appropriate coverage.
UnityCare IT helps healthcare organizations gather accurate information for insurance applications, close common control gaps and document what is in place. We are not insurance brokers, but we are happy to work with yours. If a renewal is coming up, start the conversation early.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172